The cost structure nobody else in security carries
An average security operations centre receives more than eleven thousand alerts a day. That figure is quoted often enough to have lost its force, so read it as a provider rather than as an enterprise: it is the load of one customer. A practice with ten of them is carrying the alert volume of ten enterprises, investigated by one team, under contracts that promise a response time to each of them separately.
No other part of the security market has that shape. An enterprise security team's workload grows with its own estate, which grows slowly and with warning. A provider's workload grows the day a contract is signed, in a step, and the step is the size of somebody else's entire company.
That is why the usual levers do not work for long. Better detection content raises the volume. Tuning trades missed detections for a shorter queue. Both are worth doing and neither changes the shape of the curve, because the curve is set by how many alerts a person can work in a shift and how many shifts you are willing to pay for.
Derived from the widely cited figure of more than eleven thousand alerts a day for an average SOC.
The stage where the hours actually go
Break a single alert into its three stages and the arithmetic becomes obvious. Detection is already automatic, which is why there are eleven thousand of them. Containment is quick once somebody has decided what to do. Between those two sits the investigation: forming a hypothesis, opening five to twelve consoles, pivoting across endpoint, identity, cloud and network, and deciding what actually happened.
A manual investigation of that kind runs 60 to 90 minutes. That is the number to multiply, not the alert count. A practice does not pay for alerts, it pays for the hours spent understanding them, and those hours are the only line on the cost sheet that scales with every customer signed.
Set against that, the hiring answer has run out. There are roughly three and a half million unfilled cybersecurity roles worldwide. A growth plan that requires recruiting experienced analysts faster than the market can supply them is not a plan, it is a hope with a headcount attached.
Automation of the wrong stage
Most of what the market calls SOC automation automates the parts that were never the bottleneck. Ticket creation was automated years ago. Enrichment lookups, notification, assignment, the monthly report: all of it useful, none of it the stage that consumes the shift.
The newer offer is summarisation. A model reads the alert and writes a paragraph about it, and the paragraph is good. It shortens the write-up rather than the work, and the write-up was never the expensive part. An analyst who reads a fluent summary of an alert still has to go and find out whether the thing described actually happened.
The test is simple and unkind. If a tool were removed tomorrow, would the rota change? Automation that does not let you run the same book of business with a different number of analyst hours has not touched the cost structure, whatever it did to the experience of working there.
- Automated alerting: solved long ago, and the reason the volume is what it is.
- Automated enrichment: real time saved, measured in minutes per alert rather than the hour that matters.
- Automated summarisation: shortens the report, not the investigation that the report describes.
- Automated investigation: the only one of the four that changes how many alerts a shift can absorb.
What happens to the curve when the middle stage goes
When agents perform the investigation rather than assist with it, the same work runs in 60 to 120 seconds instead of 60 to 90 minutes, and it runs on every qualified alert across every tenant rather than on the ones a person reached. The analyst receives a complete investigation instead of a queue position.
The commercial consequence is not that the team is faster. It is that signing a customer stops obliging you to add hours. Investigation capacity is already present and is not consumed per contract in the way a rota is, so the marginal cost of the next tenant becomes a question of scope rather than of recruitment.
That also settles the quality argument that customers raise in every renewal. Consistency stops being a property of the rota and becomes a property of the platform: the same structured evidence collection and timeline reconstruction on every alert, whichever shift received it, which is a far easier thing to defend in a service review than a promise about training.
Where margin quietly leaks besides the queue
Two other lines cost more than most practices model. The first is onboarding. Every tenant that takes weeks of connector and content work delays the revenue and consumes the same scarce engineers who would otherwise be building the service. Prebuilt coverage across 250 or more log sources turns that from a project into a configuration, which moves the revenue forward by the length of the project.
The second is reporting. Investigation reports, executive summaries and the compliance documentation a customer's auditors ask for consume senior time and generate no margin at all. When the evidence is produced as the work happens, with the verdict, the timeline and the affected entities already attached, the report becomes a by-product rather than a task.
Neither of these is glamorous and both are visible in the accounts. A practice that has automated investigation but still assembles every report by hand has moved its bottleneck rather than removed it.
Isolation is a commercial requirement, not a feature
One constraint sits above all of this and cannot be traded against margin. Tenant separation is a contractual and often regulatory obligation, and it is tested by the customer's own risk function rather than admired in a datasheet.
A shared store with access filters is defensible right up until somebody asks how the filter is enforced and what happens when it is misconfigured. Tenant-level separation in the architecture is defensible because there is nothing to enforce, and the difference shows up in how long a security questionnaire takes to clear.
The same applies to where the platform runs. A book of business is rarely uniform: one customer is happy in shared cloud, another has a regulator with an opinion about residency, and a third cannot send telemetry anywhere at all. If those three need three toolchains, the third customer is unprofitable before the first alert arrives.
- Separation that is structural rather than a filtered view of a shared store.
- One console for the provider across every tenant, with per-tenant policy behind it.
- Reporting produced from a single customer's evidence, ready to go out under your brand.
- The same platform for a shared-cloud tenant and an air-gapped one, so a regulated customer is not a second practice.
How to price it once the arithmetic changes
Providers who make this transition tend to discover that their pricing model was a proxy for their cost model. Per-device and per-seat pricing existed because analyst hours scaled with devices and seats. When they stop doing so, the pricing can follow the value rather than the labour.
The practical move is to price against scope and outcome: what is covered, what the service is permitted to do without asking, what the evidence pack contains and how fast containment happens. Those are things a customer can evaluate and a competitor cannot trivially undercut, whereas an hourly cost structure invites exactly the race that has compressed this market.
It also changes who the addressable customer is. A mid-market organisation that could never fund a security operation of its own becomes servable at a price it can pay, because the cost of serving it is no longer a fraction of a senior analyst's week.
The honest version
None of this makes a managed practice easy. The customer relationship, the escalation path, the service levels, the judgement calls on what to contain during business hours: all of it stays, and all of it is where a good provider earns its reputation.
What changes is the one line that has been quietly deciding whether the business works. A practice whose cost per tenant is set by how many hours a person spends understanding alerts is priced by the labour market. A practice where that stage runs at machine speed is priced by what it covers.
That is the whole argument, and it is narrower than the marketing around it. Not that AI improves managed security in the abstract, but that investigation is the stage the margin lives in, and it is the one stage that a faster console, a better summary and a bigger rota all leave exactly where it was.
Frequently asked questions
Why does an MSSP's cost structure differ from an enterprise security team's?
An enterprise carries the alert volume of its own estate, which grows slowly. A provider carries the combined volume of every customer, and it grows in a step the day each contract is signed. With an average SOC receiving more than eleven thousand alerts a day, a book of ten customers is investigating the load of ten enterprises with one team, under separate response-time commitments to each.
Which stage of alert handling actually consumes the hours?
The investigation between detection and containment. Detection is automatic, which is why the volume is what it is, and containment is quick once a decision exists. The investigation is where an analyst forms a hypothesis, pivots across endpoint, identity, cloud and network, and decides what happened, and it typically runs 60 to 90 minutes per qualified alert.
Does SOC automation reduce the cost per tenant?
It depends entirely on what is automated. Ticket creation, enrichment, notification and reporting all save time without changing how many alerts a shift can absorb. Automating the investigation itself is the only one that changes the rota, because it is the only one that removes the hour rather than shortening the minutes around it.
How much faster is an autonomous investigation?
A manual investigation that runs 60 to 90 minutes becomes a typical autonomous cycle of 60 to 120 seconds, and it runs on every qualified alert across every tenant rather than on the ones a person reached. The commercial effect is that signing a customer stops obliging a provider to add analyst hours.
Why is tenant separation a commercial issue rather than a technical one?
Because it is tested by the customer's risk function during procurement and renewal, and the answer determines how long a security questionnaire takes to clear. Separation built into the architecture is defensible because there is nothing to enforce, while a shared store with access filters invites questions about how the filter is enforced and what happens when it is misconfigured.
What should a managed provider price against once investigation is automated?
Scope and outcome rather than labour: what is covered, what the service may do without asking, what the evidence pack contains, and how quickly containment happens. Per-device and per-seat pricing existed as a proxy for analyst hours scaling with devices and seats, and when that stops being true the pricing can follow what the customer actually buys.
AI SOC for MSSPs and MDR providers
Multi-tenant investigation, white label delivery and the deployment each customer needs.
AI SOC for MSSPs
The platform side of everything argued here.
Partner programme
How providers sell and deliver SOC as a Service on Spharaka.
Alert triage automation
The stage the margin lives in, as a capability.
Breakout in 29 minutes
The same interval, argued from the attacker's clock rather than the cost sheet.


